Skip to main content
Back to overview
Medium

Workday confirms data breach from social engineering attack on third-party CRM

Workday confirmed a data breach stemming from a social engineering attack targeting a third-party Customer Relationship Management (CRM) system.

Key points

  • Social engineering attack.
  • Third-party CRM system compromised.
  • Business contact information exposed (names, emails, phone numbers).

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Threat source not confirmed

03

Potential impact

Potential fraud or account takeover risk

Confidentiality

Published
Aug 20, 2025
Updated
Jun 26, 2026
Confidence
Medium
Evidence
1 source

Structured assessment

Signal analysis

It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch phishing, executive impersonation and account-takeover exposure.

Business impact

Potential fraud or account takeover risk
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

WorkdayData DisclosureWorkdayCRM WorkdayCustomer Relationship ManagementCRMShinyHuntersScattered SpiderSocialThird-party CRM

Quick context

Questions about this signal

What happened in this signal?

Workday confirmed a data breach stemming from a social engineering attack targeting a third-party Customer Relationship Management (CRM) system. The breach, reported on August 20, 2025 (after initial disclosure on August 15), compromised business contact information including names, email addresses, and phone numbers, but did not impact customer tenants or their secure data. The attack is linked to the ShinyHunters/Scattered Spider groups.

When was this signal reported?

Shadow Tier lists Aug 20, 2025 as the signal date.

Which organization is connected to this signal?

Workday is the organization connected to this public signal.

Explore Workday
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence